Today we are open-sourcing @sigma_hq rule packages for AWS S3 and GCP BigQuery.
We have taken the detective controls from our threat models, the ones that already say exactly what to look for in the logs, and expressed them as Sigma rules so customers can deploy them without rewriting the logic by hand.
This release covers 15 AWS S3 controls and 4 GCP BigQuery controls, all built on the native cloud log source (CloudTrail for AWS, Cloud Logging for GCP).
Learn more: https://t.co/bTa9WPYZyI
#sigma #aws #gcp #controls #cloudsec #trustoncloud
🦟New Blog: Confused Deputy Flaw in Amazon DataZone
The TrustOnCloud team identified a critical Confused Deputy vulnerability in Amazon DataZone, potentially allowing unauthorized access across AWS accounts.
Full details: https://t.co/wB1T0BaUnk #CloudSecurity#AmazonDataZone #Cybersecurity #TrustOnCloud
🎉Delighted to announce that we have been featured on Latio's esteemed "Boundary Breakers" list! Latio Tech is on a mission to help organizations discover the best security tools, completely free from vendor bias.
💙 Love what we do? We'd appreciate your support by upvoting us on the 'Boundary Breakers' list. You can also explore other outstanding tools listed that could enhance your security posture.
Learn more➡️ https://t.co/3Ogt2GbqmZ
#TrustOnCloud #CloudSecurity #Innovation
🛡️New Blog: How I bypassed the control plane in Azure OpenAI
While completing the ThreatModel for Microsoft Azure OpenAI, our CTO Tyson Garrett discovered a way to allow the management of Azure OpenAI deployments via the Data Plane, resulting in the loss of significant security controls.
Read more➡️ https://t.co/J3T1j5jhHP
#openai #threatmodel #azure #cloudsecurity #Microsoft #APIsecurity #API #Cyber
@trustoncloud@TMConnectHQ A packed room and a great event. It really shows the eagerness of the industry on practical threat modeling!A packed room and a great event. It really shows the eagerness of the industry on practical threat modeling!
This #CyberSecurityAwarenessMonth, enhance your cloud security with a free threat model from our 140+ offerings. You can streamline your cloud transition and navigate its intricacies with ease.
Claim your Free ThreatModel➡️ https://t.co/HknJaYdkX3 #CloudSecurity#TrustOnCloud
Stay on top of cloud security knowledge with TrustOnCloud! 120+ services, easy-to-explore threat models, and quarterly updates. Get confident through knowledge!
TrustOnCloud's ThreatModels are now on AWS Marketplace & Data Exchange!
💵 Accelerate procurement & enable EDP
🔒 Simplify secure data delivery
Explore: https://t.co/LIzOVTtpkH
Free S3 ThreatModel soon! Azure next? 😉
#CloudSecurity#ThreatModeling#AWS#TrustOnCloud
NEW BLOG: Want to hack Amazon Cognito?
Our team has developed a lab for @RhinoSecurity#CloudGoat that lets you hack two common security misconfigurations using #awscloud Cognito.
Read the walkthrough https://t.co/E0cIBderf8
#cloudsecurity
@uptill_3@AWSSupport AWS has some level of durability. But for the shared responsabilty: depends on you, if you care not to lose any with high certainty (e.g., worried about attackers deleting the logs?), or if you have regulatory requirements, then yes. There is an export to S3 BTW.
@0xdabbad00 +1, MFA Delete is a control we specifically excluded from the open-source S3 ThreatModel because of its legacy design (see S3.T16 for ransomware on https://t.co/5tnUVXeR35)